Repository navigation
hftools v0.12.0
Signing identity and trusted keys
Provenance signing now has a persistent per-user identity, so sign and verify-sig no longer require juggling PEM key paths, and a recipient can pin a signer by name.
~/.hftoolshome store (override with$HFTOOLS_HOME): an ed25519 private key (signing.key, mode 0600), its public key (signing.pub), and aconfig.yamlholding the signer label and atrusted_keysregistry. Still zero external dependencies —config.yamluses a small built-in YAML reader.signwith no--keyuses the home identity, creating it (key +config.yaml) on first run, and defaults the signer label from config.verify-sigauto-recognizes a signer whose key you have trusted (reportstrusted key: NAME);--pubkeynow also accepts a trusted name. It always prints the key's SHA-256 fingerprint, and when the key is unpinned/untrusted it suggests thekey trustcommand.- New
keycommand:init,show,export,trust,untrust,list,path.
# Signer — first sign creates ~/.hftools automatically:
hftools sign --output ./owner_model --signer you@example.com
hftools key export --out mykey.pem # public key to distribute
# Recipient — trust the signer's key once, then verify:
hftools key trust alice mykey.pem
hftools verify-sig --output ./owner_model # auto-recognizes the trusted keyHashing proves a download is intact; a trusted signature proves who produced it — useful across an air gap.
Static binaries for macOS, Windows, and Linux on ARM64 and x86-64. Verify a download against SHA256SUMS.